ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Third-Party Content License Register

Third-Party Content License Register

1. Purpose

The Third-Party Content License Register provides a centralized record of third-party content used, stored, published, distributed, or incorporated by the organization.

The register helps the organization:

  • Identify third-party content
  • Identify the content owner
  • Record the applicable license or permission
  • Verify permitted use
  • Track attribution requirements
  • Identify usage restrictions
  • Track license expiry
  • Prevent unauthorized use
  • Support customer and commercial requirements
  • Manage copyright and intellectual-property risk
  • Support audits and legal reviews
  • Support content removal when rights expire

Core Principle

Identify → Verify Ownership → Verify License → Understand Rights → Record Restrictions → Approve Use → Monitor → Renew/Remove → Preserve Evidence


2. When to Use

Use this register for third-party content such as:

  • Images
  • Photographs
  • Stock images
  • Videos
  • Audio
  • Music
  • Fonts
  • Icons
  • Graphics
  • Illustrations
  • Templates
  • Documents
  • Reports
  • Articles
  • Research material
  • Datasets
  • Maps
  • Charts
  • Presentations
  • Training material
  • Marketing content
  • Website content
  • Customer-provided content
  • Third-party logos
  • Software documentation
  • Media assets
  • AI-generated or AI-assisted content where third-party rights may be relevant

3. Register Information

FieldDetails
Register NameThird-Party Content License Register
Register Owner
Business Owner
Legal/Compliance Owner
Version
Effective Date
Last Review Date
Next Review Date
Approved By

4. Master Content Register

Content IDContent NameTypeSourceOwnerLicenseBusiness OwnerStatus

Status

☐ Active
☐ Under Review
☐ Restricted
☐ Expired
☐ Removed
☐ Retired
☐ Exception


5. Content Identification

Record enough information to uniquely identify the content.

FieldDetails
Content ID
Content Name
Description
Content Type
File Name
Version
URL/Source
Date Obtained
Date Added
Location Used
Business Owner

Do not rely only on a filename such as image-final.jpg. Record the actual source and rights information.


6. Content Type

☐ Image
☐ Photograph
☐ Video
☐ Audio
☐ Music
☐ Font
☐ Icon
☐ Illustration
☐ Graphic
☐ Template
☐ Document
☐ Article
☐ Research
☐ Dataset
☐ Map
☐ Chart
☐ Presentation
☐ Logo
☐ Training Material
☐ Other: __________________


7. Source Information

Record where the content was obtained.

FieldDetails
Source Website/Platform
Original Creator
Publisher
Content URL
Download Date
Purchased From
Account Used
Source Verification

Source Type

☐ Stock provider
☐ Creator directly
☐ Customer
☐ Supplier
☐ Public website
☐ Government source
☐ Creative Commons source
☐ Open-content repository
☐ Internal employee/contractor
☐ Other: __________________


8. Ownership Verification

Determine who owns or controls the rights.

☐ Original creator identified
☐ Copyright owner identified
☐ Publisher identified
☐ Rights holder verified
☐ Ownership documentation available
☐ License provider verified
☐ No ownership uncertainty identified

Rights Holder

Name/Organization: ____________________

Evidence: _____________________________


9. License Information

Record the applicable license or permission.

FieldDetails
License Name
License Type
License Provider
License Version
License URL/Reference
License Start Date
License Expiry Date
Purchase/Order ID
License Evidence

10. License Category

☐ Commercial license
☐ Subscription license
☐ Royalty-free license
☐ Rights-managed license
☐ Creative Commons
☐ Public domain
☐ Open-content license
☐ Direct permission
☐ Customer-provided license
☐ Supplier-provided license
☐ Internal permission
☐ Other: __________________

Do not assume that “free”, “royalty-free”, or “publicly available” automatically means unrestricted use.


11. Permitted Use

Record exactly how the organization is permitted to use the content.

☐ Internal use
☐ Website
☐ Mobile application
☐ Software product
☐ Marketing
☐ Social media
☐ Advertising
☐ Training
☐ Presentation
☐ Customer deliverable
☐ Commercial distribution
☐ Resale
☐ Modification
☐ Derivative works
☐ Print
☐ Broadcast
☐ Other: __________________


12. Geographic Rights

Determine where the content may be used.

☐ Worldwide
☐ Specific countries
☐ Specific regions
☐ Internal jurisdiction only
☐ Customer-specific geography
☐ Other: __________________

Geographic Restrictions


13. Distribution Rights

Determine whether the content may be distributed externally.

☐ Internal only
☐ Customer-facing
☐ Public website
☐ Commercial product
☐ Marketing campaign
☐ Resale permitted
☐ Redistribution prohibited
☐ Embedded in software
☐ Embedded in customer deliverables

Distribution Notes


14. Modification Rights

Determine whether the organization may modify the content.

☐ Modification permitted
☐ Modification restricted
☐ Derivative works permitted
☐ Derivative works prohibited
☐ Cropping permitted
☐ Editing permitted
☐ Branding permitted
☐ Translation permitted
☐ Other: __________________


15. Attribution Requirements

Determine whether attribution is required.

☐ Attribution not required
☐ Attribution required
☐ Creator attribution required
☐ License attribution required
☐ Copyright notice required
☐ Source link required
☐ Specific wording required

Required Attribution

Attribution Location

☐ Website
☐ Application
☐ Documentation
☐ Marketing material
☐ Credits
☐ Customer deliverable
☐ Other: __________________


16. Usage Restrictions

Record important restrictions.

☐ Commercial use prohibited
☐ Resale prohibited
☐ Redistribution prohibited
☐ Modification prohibited
☐ AI training prohibited
☐ Sensitive-use restrictions
☐ Political-use restrictions
☐ Adult-content restrictions
☐ Trademark restrictions
☐ Endorsement restrictions
☐ Geographic restrictions
☐ Platform restrictions
☐ Other: __________________

Restrictions


17. Model/Property Releases

For photographs, videos, or other content involving identifiable people or protected property, assess whether additional permissions are relevant.

☐ Model release available where required
☐ Property release available where required
☐ No release required based on use/rights assessment
☐ Release status unknown
☐ Legal review required

Evidence


18. Trademark and Branding Review

If third-party logos, trademarks, or branding are used:

☐ Trademark owner identified
☐ Permission/license confirmed
☐ Permitted use documented
☐ Brand guidelines reviewed
☐ Customer/supplier authorization confirmed where applicable
☐ Misleading endorsement risk considered


19. Fonts

For third-party fonts:

☐ Font owner identified
☐ License identified
☐ Web use permitted
☐ Application use permitted
☐ Commercial use permitted
☐ Embedding permitted
☐ Modification permitted
☐ Redistribution restrictions reviewed
☐ License evidence retained

Font Record

FontProviderLicenseUseEmbeddingRestrictions

20. Images and Photography

For images:

☐ Source identified
☐ Creator identified
☐ License verified
☐ Commercial use verified
☐ Modification rights verified
☐ Attribution requirement checked
☐ Model/property rights assessed where relevant
☐ Storage location recorded


21. Video and Audio

For video/audio:

☐ Source verified
☐ Copyright owner identified
☐ License verified
☐ Commercial use permitted
☐ Editing permitted
☐ Distribution permitted
☐ Public performance/broadcast rights considered where relevant
☐ Attribution requirements identified
☐ Music licensing requirements assessed


22. Documents and Written Content

For third-party written material:

☐ Author identified
☐ Publisher identified
☐ Copyright status assessed
☐ License/permission verified
☐ Permitted use documented
☐ Reproduction rights reviewed
☐ Modification rights reviewed
☐ Attribution requirements reviewed
☐ Customer distribution assessed

Avoid copying or republishing third-party content merely because it is publicly accessible.


23. Datasets

For third-party datasets:

☐ Dataset owner identified
☐ Dataset license identified
☐ Permitted use verified
☐ Commercial use assessed
☐ Redistribution assessed
☐ Personal-data implications assessed
☐ Sensitive-data implications assessed
☐ Geographic restrictions reviewed
☐ Derivative-data restrictions reviewed
☐ Retention requirements reviewed

Dataset Record

DatasetProviderLicensePurposeData TypeRestrictions

24. Customer-Provided Content

If content is supplied by customers:

☐ Customer ownership documented
☐ Permitted use defined
☐ Customer authorization confirmed
☐ Confidentiality requirements identified
☐ Storage controlled
☐ Access restricted
☐ Distribution restrictions recorded
☐ Return/deletion requirements defined


25. Supplier-Provided Content

If content is supplied by a supplier:

☐ Supplier identified
☐ Ownership confirmed
☐ License confirmed
☐ Permitted use documented
☐ Restrictions documented
☐ Customer use assessed
☐ Redistribution assessed
☐ Evidence retained


26. AI-Generated or AI-Assisted Content

Where AI tools are used to create or modify content:

☐ AI tool identified
☐ Terms of use reviewed where relevant
☐ Commercial-use rights considered
☐ Input-data restrictions reviewed
☐ Customer information restrictions reviewed
☐ Third-party content restrictions considered
☐ Output ownership considerations assessed
☐ Human review completed
☐ Required attribution considered
☐ Content approval completed

AI Tool

Tool: _________________________________

Purpose: ______________________________

Rights/Restrictions: ___________________


27. Content Used in Customer Deliverables

If third-party content will be delivered to a customer:

☐ Customer contract reviewed
☐ Redistribution permitted
☐ Commercial use permitted
☐ Customer geography permitted
☐ Customer modification rights considered
☐ Attribution requirements identified
☐ License transfer/extension permitted where required
☐ Content restrictions communicated


28. Website and Marketing Use

For website and marketing content:

☐ License permits public display
☐ Commercial marketing use permitted
☐ Social-media use permitted
☐ Advertising use permitted
☐ Modification permitted
☐ Attribution requirements satisfied
☐ Geographic restrictions checked
☐ Expiry monitored


29. License Expiry

Identify content with time-limited rights.

ContentLicense ExpiryOwnerRenewal RequiredAction

Before Expiry

☐ Renew
☐ Replace
☐ Remove
☐ Confirm perpetual rights
☐ Obtain additional permission


30. Subscription-Based Content

For subscription services:

☐ Subscription active
☐ Authorized account identified
☐ Number of users checked
☐ Usage restrictions reviewed
☐ Download rights reviewed
☐ Continued-use rights after cancellation reviewed
☐ Content removal requirement understood


31. License Compliance Review

Review whether actual use matches licensed rights.

☐ Content still used for permitted purpose
☐ Geographic use remains permitted
☐ Distribution remains permitted
☐ User/customer population remains permitted
☐ Modification remains permitted
☐ Attribution remains satisfied
☐ License remains valid
☐ Restrictions remain satisfied


32. Unauthorized Content Review

Identify content where license information is missing or uncertain.

ContentSourceIssueRiskActionOwner

Possible actions:

☐ Verify license
☐ Obtain permission
☐ Purchase license
☐ Replace content
☐ Remove content
☐ Obtain legal review


33. Content Risk Assessment

Assess risks associated with important third-party content.

RiskLikelihoodImpactRatingTreatment
Copyright infringement
Unauthorized commercial use
License expiry
Missing attribution
Unauthorized redistribution
Trademark misuse
Customer contract violation
Unknown ownership

34. License Evidence

Retain appropriate evidence such as:

☐ License agreement
☐ Purchase receipt
☐ Subscription record
☐ Permission email
☐ Creator authorization
☐ Download record
☐ License page/archive
☐ Terms of use
☐ Attribution record
☐ Model/property release
☐ Customer authorization
☐ Supplier confirmation

Where possible, preserve evidence of the license applicable at the time the content was obtained and used.


35. Content Approval

For material third-party content:

Content ID: ___________________________

Business Owner: ________________________

License Reviewed By: ___________________

Legal/Compliance Review: ______________

Approved Use: _________________________

Approval Date: _________________________


36. Exceptions

Record cases where content is used despite a known restriction or unresolved issue.

ExceptionContentReasonRiskCompensating ControlExpiryApprover

Exceptions should have a defined owner and review/expiry date where practical.


37. Content Removal

When rights expire or use is no longer permitted:

☐ Website content removed
☐ Application content removed
☐ Marketing material updated
☐ Social-media material reviewed
☐ Documentation updated
☐ Customer deliverables reviewed
☐ Local copies removed where required
☐ Repository copies removed where required
☐ Replacement content identified
☐ Removal evidence retained


38. Periodic Review

Review the register periodically.

Check:

☐ Active licenses
☐ Expired licenses
☐ New content
☐ Changed terms
☐ Changed usage
☐ Attribution
☐ Customer distribution
☐ Commercial use
☐ Geographic restrictions
☐ Subscription status
☐ Content ownership
☐ Exceptions
☐ Content requiring removal


39. Review Triggers

An additional review may be required when:

☐ License terms change
☐ Content use changes
☐ Content becomes customer-facing
☐ Content becomes commercially distributed
☐ New geography is introduced
☐ New customer requirements apply
☐ New marketing campaign starts
☐ Subscription ends
☐ Ownership changes
☐ Copyright concern is raised
☐ Content complaint is received
☐ Third-party claim is received
☐ Organization acquires another business
☐ AI-generated content is introduced


40. Corrective Action Register

Action IDContentFindingRiskActionOwnerDue DateStatus

41. Register Summary

CategoryTotalActiveExpiringExpiredReview Required
Images
Videos
Audio
Fonts
Documents
Datasets
Logos/Trademarks
Other

42. AWS SaaS Startup Example

An AWS SaaS startup uses third-party content across its website, application, documentation, and marketing material.

Example Register

ContentTypeSourceLicenseIntended UseStatus
Product illustrationImageStock providerCommercialWebsiteActive
Company fontFontFont providerCommercialWebsiteActive
Training datasetDatasetExternal providerResearch/CommercialML developmentReview
Product icon setIconsThird-party providerCommercialApplicationActive
Customer logoTrademarkCustomerPermissionWebsiteActive

Review

The startup verifies:

  • Who owns each asset
  • What license applies
  • Whether commercial use is allowed
  • Whether modification is allowed
  • Whether attribution is required
  • Whether the content can be distributed to customers
  • Whether the license expires
  • Whether the actual use matches the license

Audit Trail

Content Identified → Owner Verified → License Verified → Permitted Use Confirmed → Restrictions Recorded → Approval → Usage Monitoring → Periodic Review → Renewal/Removal


43. Startup-Friendly Model

A startup does not need an unnecessarily complicated process.

For each important third-party asset, capture at least:

Required InformationExample
What is it?Product image
Where did it come from?Stock provider
Who owns it?Provider/creator
What license applies?Commercial
What can we do with it?Website/marketing
What can’t we do?Resale
Is attribution required?No
Does it expire?Yes/No
Who owns the record?Marketing
Where is the evidence?License repository

Minimum Rule

No Unknown Source + No Unknown License + No Unapproved Commercial Use


44. Common Mistakes

Avoid:

  • Assuming internet availability means permission to use.
  • Treating “royalty-free” as “copyright-free.”
  • Failing to record the source.
  • Failing to retain license evidence.
  • Using stock assets outside the licensed purpose.
  • Ignoring geographic restrictions.
  • Ignoring attribution requirements.
  • Using customer logos without appropriate permission.
  • Redistributing licensed content to customers without checking rights.
  • Forgetting fonts and icons.
  • Ignoring datasets.
  • Assuming AI-generated content has no third-party IP considerations.
  • Continuing to use content after a subscription/license ends.
  • Keeping old content on websites after license expiry.
  • Allowing marketing teams to independently source unverified content.

45. Relationship With Other ISMS Documents

DocumentRelationship
Intellectual Property Protection PolicyDefines IP protection requirements
Intellectual Property RegisterRecords important organizational IP
Software License RegisterTracks software licensing
Open-Source Software RegisterTracks open-source components
Open-Source License Review ChecklistReviews OSS licensing
Copyright & Licensing ProcedureDefines licensing processes
Customer Contract Security ReviewIdentifies customer content obligations
Supplier Security AssessmentAssesses supplier-provided content
Information Classification PolicyClassifies sensitive content
Records Retention PolicyDefines retention requirements
Marketing Content Review ProcedureControls public content use
Legal & Regulatory Requirements RegisterTracks applicable legal requirements
Risk RegisterTracks significant IP/licensing risks

46. ISO/IEC 27001 Connection

Third-party content licensing supports the organization’s risk-based management of:

  • Intellectual property
  • Legal and contractual requirements
  • Information assets
  • Information classification
  • Supplier relationships
  • Information transfer
  • Customer requirements
  • Records and evidence
  • Access and use restrictions

The Third-Party Content License Register is not itself a universally mandatory ISO/IEC 27001 document.

The organization should determine the appropriate level of content licensing control based on:

  • Business risk
  • Content type
  • Intended use
  • Customer requirements
  • Commercial distribution
  • Applicable law
  • Contractual obligations
  • Geographic scope

Applicable controls should be addressed through the organization’s risk assessment and Statement of Applicability.


47. Audit Evidence

An auditor may expect the organization to demonstrate, where relevant:

☐ Third-party content inventory
☐ Ownership information
☐ License evidence
☐ Usage rights
☐ Attribution records
☐ Approval records
☐ Customer permissions
☐ License-expiry monitoring
☐ Exception records
☐ Content removal evidence
☐ Corrective actions
☐ Periodic reviews


48. Final Third-Party Content Audit Trail

For significant third-party content, the organization should be able to demonstrate:

What content are we using?
Where did we obtain it?
Who owns it?
What license or permission applies?
What are we allowed to do with it?
What restrictions apply?
Is attribution required?
Can we use it commercially?
Can we modify it?
Can we distribute it to customers?
Does the license expire?
Who approved the use?
Where is the license evidence?
What happens when the rights expire?


49. Final Principle

Know the Content → Know the Owner → Know the License → Know the Permitted Use → Record Restrictions → Approve → Monitor → Renew or Remove → Preserve Evidence

A third-party content register should not become just another spreadsheet. It should provide a defensible connection between content source, ownership, licensing rights, actual use, business approval, customer commitments, expiry, and removal.